US7080256B1ExpiredUtility

Method for authenticating a chip card in a message transmission network

Assignee: GIESECKE & DEVRIENT GMBHPriority: May 7, 1998Filed: Apr 27, 1999Granted: Jul 18, 2006
Est. expiryMay 7, 2018(expired)· nominal 20-yr term from priority
Inventors:Klaus Vedder
G07F 7/1008G06Q 20/40975H04L 63/0853G06Q 20/341H04W 12/069Y04S40/20
47
PatentIndex Score
29
Cited by
4
References
10
Claims

Abstract

The invention relates to a method for authenticating a smart card (SIM) in a messaging network, preferably a GSM network, wherein an optionally secret algorithm and a secret key are stored in a smart card (SIM), whereby for authentication the network or a network component first transfers a random number to the smart card, a response signal is generated in the smart card by means of the algorithm, the random number and the secret key, said signal being transmitted to the network or network component in order to check the authenticity of the card there. According to the invention both the secret key and the random number transferred by the network are split into at least two parts to form the authentication message, one part of the transferred random number and one or more parts of the secret key being encrypted by means of a one- or multistep, preferably symmetrical calculation algorithm. To output an authentication response, a selectable part of the encryption result is transferred to the network.

Claims

exact text as granted — not AI-modified
1. A method for authenticating a smart card (SIM) in a messaging network, wherein an algorithm and a secret key are stored in a smart card (SIM), whereby for authentication
 the network or a network component first transfers a random number (RAND) to the smart card, 
 a response signal (SRES) is generated therefrom in the smart card by means of the algorithm and the secret key (K i ) and transmitted to the network or network component, characterized in that 
 to form the response signal (SRES) the secret key (K i ) and the random number (RAND) are each split into at least two parts (K 1 , K 2 ; RAND 1 , RAND 2 ), 
 one of the parts (RAND 1 , RAND 2 ) of the transferred random number (RAND) is encrypted with the aid of one or more parts (K 1 , K 2 ) of the secret key (K i ) by means of a one- or multistep algorithm. 
 
   
   
     2. A method according to  claim 1 , characterized in that a given number of bits is selected from the encryption result and transferred as a signal response (SRES) to the network. 
   
   
     3. A method according to  claim 1 , characterized in that a part of the transferred random number (RAND) and one or more parts of the secret key (K i ) are used to calculate a channel coding key (K c ) by means of a one- or multistep algorithm, at least one part of the calculation result being used as the channel coding key (K c ). 
   
   
     4. A method according to  claim 1 , characterized in that the key (K 1 ) and the random number (RAND) are split into two equally long parts (K 1 , K 2 /RAND 1 , RAND 2 ). 
   
   
     5. A method according to  claim 1 , characterized in that DES algorithms are used to calculate at least one of the authentication parameters (SRES, SRES′) and the channel coding key (K c ). 
   
   
     6. A method according to  claim 1 , characterized in that an IDEA algorithm is used to calculate the authentication parameters (SRES, SRES′) and the channel coding key (K c ). 
   
   
     7. A method according to  claim 1 , characterized in that a compression algorithm whose output value has a smaller length than the input parameter is used to calculate the authentication parameters (SRES, SRES′) and the channel coding key (K c ). 
   
   
     8. A method according to  claim 7 , characterized in that the calculation of the authentication parameters is effected in an at least two-step algorithm. 
   
   
     9. A method according to  claim 1 , characterized in that a triple DES algorithm is used as an encryption algorithm, whereby one first encrypts with the first part (K 1 ) of the key (K i ), then decrypts with the second part (K 2 ) of the key (K i ) and thereupon encrypts again with the first part (K 1 ) or a third part of the key (K i ), by means of a one- or multistep algorithm. 
   
   
     10. A method according to  claim 1 , characterized in that a selection of the first or second part of the random number (RAND) is effected in the same way in the card and the network in random or pseudorandom alternation.

Join the waitlist — get patent alerts

Track US7080256B1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.